There's nothing anyone can do if a user installs software. UNIX design or not, if the user runs a program, it can access everything that the user can. Nothing that this malware did needed special access (e.g. root exploit).
The idea that all apps run under a single "user" and all share the permissions of that "user" is just how UNIX does it, not how things must work. I don't think we've figured out proper app sandboxing yet (Mac, iOS, and Android all have their problems with it, and differently) but it seems to be the way to go.
- a recent convert to Apple
However, this will break nearly everything – and I am rather positive that Windows offers similar security measures, if required.
Now the malware problems on both platforms rarely rely on privilege escalation. They use trojan horses instead, and wait for you to install them.